惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

酷 壳 – CoolShell
酷 壳 – CoolShell
H
Hacker News: Front Page
P
Palo Alto Networks Blog
T
ThreatConnect
Apple Machine Learning Research
Apple Machine Learning Research
博客园_首页
T
True Tiger Recordings
P
Privacy & Cybersecurity Law Blog
B
Blog
IT之家
IT之家
Last Week in AI
Last Week in AI
F
Full Disclosure
Hacker News: Ask HN
Hacker News: Ask HN
C
Comments on: Blog
Microsoft Azure Blog
Microsoft Azure Blog
C
Cybersecurity and Infrastructure Security Agency CISA
Microsoft Security Blog
Microsoft Security Blog
博客园 - 【当耐特】
N
News and Events Feed by Topic
NISL@THU
NISL@THU
腾讯CDC
雷峰网
雷峰网
Security Latest
Security Latest
李成银的技术随笔
M
Microsoft Research Blog - Microsoft Research
L
LangChain Blog
L
Lohrmann on Cybersecurity
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
C
Check Point Blog
Y
Y Combinator Blog
Recent Announcements
Recent Announcements
博客园 - Franky
N
News | PayPal Newsroom
V
V2EX
A
About on SuperTechFans
The Register - Security
The Register - Security
月光博客
月光博客
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Google Online Security Blog
Google Online Security Blog
MyScale Blog
MyScale Blog
Cisco Talos Blog
Cisco Talos Blog
Vercel News
Vercel News
WordPress大学
WordPress大学
C
Cyber Attacks, Cyber Crime and Cyber Security
The Hacker News
The Hacker News
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
爱范儿
爱范儿
A
Arctic Wolf
L
LINUX DO - 最新话题
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More

WeLiveSecurity

The quest for greater tech independence Why geopolitical turmoil is a gift for scammers, and how to stay safe FrostyNeighbor: Fresh mischief and digital shenanigans Eyes wide open: How to mitigate the security and privacy risks of smart glasses Fake call logs, real payments: How CallPhantom tricks Android users Fixing trivial passwords is as easy as 123456 A rigged game: ScarCruft compromises gaming platform in a supply-chain attack This month in security with Tony Anscombe – April 2026 edition The calm before the ransom: What you see is not all there is GopherWhisper: A burrow full of malware New NGate variant hides in a trojanized NFC payment app Ransomware’s back office: What the ransom note won’t say Why that next data breach alert could be a trap Supply chain dependencies: Have you checked your blind spot? Recovery scammers hit you when you’re down: Here’s how to avoid a ‘second strike’ As breakout time accelerates, prevention-first cybersecurity takes center stage Digital assets after death: Managing risks to your loved one’s digital estate This month in security with Tony Anscombe – March 2026 edition RSAC 2026 wrap-up – Week in security with Tony Anscombe A cunning predator: How Silver Fox preys on Japanese firms this tax season Virtual machines, virtually everywhere – but not all protected Cloud workload security: Mind the gaps Move fast and save things: A quick guide to recovering a hacked account EDR killers explained: Beyond the drivers Face value: What it takes to fool facial recognition Cyber fallout from the Iran war: What to have on your radar Sednit reloaded: Back in the trenches What cybersecurity actually does for your business Protecting education: How MDR can tip the balance in favor of schools This month in security with Tony Anscombe – February 2026 edition Mobile app permissions (still) matter more than you may think Faking it on the phone: How to tell if a voice call is AI or not PromptSpy ushers in the era of Android threats using GenAI Is Poshmark safe? How to buy and sell without getting scammed Is it OK to let your children post selfies online? Naming and shaming: How ransomware groups tighten the screws on victims Taxing times: Top IRS scams to look out for in 2026 OfferUp scammers are out in force: Here’s what you should know A slippery slope: Beware of Winter Olympics scams and other cyberthreats This month in security with Tony Anscombe – January 2026 edition DynoWiper update: Technical analysis and attribution Love? Actually: Fake dating app used as lure in targeted spyware campaign in Pakistan Drowning in spam or scam emails lately? Here’s why ESET Research: Sandworm behind cyberattack on Poland’s power grid in late 2025 Children and chatbots: What parents should know Common Apple Pay scams, and how to stay safe Old habits die hard: 2025’s most common passwords were as predictable as ever Why LinkedIn is a hunting ground for threat actors – and how to protect yourself Is it time for internet services to adopt identity verification? Your information is on the dark web. What happens next? Credential stuffing: What it is and how to protect yourself This month in security with Tony Anscombe – December 2025 edition A brush with online fraud: What are brushing scams and how do I stay safe? Revisiting CVE‑2025‑50165: A critical flaw in Windows Imaging Component LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Japan ESET Threat Report H2 2025 Black Hat Europe 2025: Was that device designed to be on the internet at all? Black Hat Europe 2025: Reputation is currency – even in the ransomware economy Locks, SOCs and a cat in a box: What Schrödinger can teach us about cybersecurity Seeking symmetry during ATT&CK® season: How to harness today’s diverse analyst and tester landscape to paint a security masterpiece The biggest catch: How whaling attacks target top executives Phishing, privileges and passwords: Why identity is critical to improving cybersecurity posture MuddyWater: Snakes by the riverbank Oversharing is not caring: What’s at stake if your employees post too much online This month in security with Tony Anscombe – November 2025 edition What parents should know to protect their children from doxxing Influencers in the crosshairs: How cybercriminals are targeting content creators MDR is the answer – now, what’s the question? The OSINT playbook: Find your weak spots before attackers do PlushDaemon compromises network devices for adversary-in-the-middle attacks What if your romantic AI chatbot can’t keep a secret? Can password managers get hacked? Here’s what to know Why shadow AI could be your biggest security blind spot In memoriam: David Harley The who, where, and how of APT attacks in Q2 2025–Q3 2025 ESET APT Activity Report Q2 2025–Q3 2025 Sharing is scaring: The WhatsApp screen-sharing scam you didn’t see coming How social engineering really works | Unlocked 403 cybersecurity podcast (S2E6) Ground zero: 5 things to do after discovering a cyberattack This month in security with Tony Anscombe – October 2025 edition Fraud prevention: How to help older family members avoid scams Cybersecurity Awareness Month 2025: When seeing isn't believing Recruitment red flags: Can you spot a spy posing as a job seeker? How MDR can give MSPs the edge in a competitive market Cybersecurity Awareness Month 2025: Cyber risk thrives in the shadows Gotta fly: Lazarus targets the UAV sector SnakeStealer: How it preys on personal data – and how to stay safe Cybersecurity Awareness Month 2025: Building resilience against ransomware Minecraft mods: When ‘hacking’ your game becomes a security risk IT service desks: The security blind spot that may put your business at risk Cybersecurity Awareness Month 2025: Why software patching matters more than ever AI-aided malvertising: How chatbots can help spread scams How Uber seems to know where you are – even with restricted location permissions Cybersecurity Awareness Month 2025: Passwords alone are not enough The case for cybersecurity: Why successful businesses are built on protection Beware of threats lurking in booby-trapped PDF files Manufacturing under fire: Strengthening cyber-defenses amid surging threats New spyware campaigns target privacy-conscious Android users in the UAE Cybersecurity Awareness Month 2025: Knowledge is power This month in security with Tony Anscombe – September 2025 edition
How SMBs use threat research and MDR to build a defensive edge
2026-03-05 · via WeLiveSecurity

Corporate IT and security teams have the unenviable task of keeping relentless and increasingly sophisticated adversaries at bay. They’re often faced with limited resources and expanding attack surfaces, but recruiting and retaining top-tier security professionals to run an in-house Security Operations Centre (SOC) is out of reach for many organizations. At the same time, threats continue to evolve and adversaries hone their techniques, leading to incidents that often grind business operations to a halt.

To avoid being caught on the back foot, defenders need an approach that’s proactive and combines prevention, detection, remediation with accurate and timely threat intelligence. If building that capability in-house is impractical, then renting or buying it as a service is a more realistic option. This isn’t a new concept, of course – smaller organizations have enjoyed the benefits of new IT innovations for decades through bureaux, managed services providers and cloud computing.

There’s a strong argument to be made for doing the same with advanced cybersecurity services, and this where Managed Detection and Response (MDR) can make a major impact. MDR gives organizations a proactive, expert-driven and scalable threat monitoring and hunting capability, without the cost of an elite SOC. Not so long ago, an MDR was expensive and complex – if less so than a dedicated in-house set-up. It’s now increasingly practical for smaller organizations to consider, too.

We recently caught up with Director of ESET Threat Research Jean-Ian Boutin to talk about the work of his team, and how threat research and intelligence feed into MDR workflows. Jean-Ian also gave us a peek into where the combination of cutting-edge technology and human expertise provides the most practical value, especially for SMB environments.

What do most small business users gain from ESET Threat Research? How does that change when they use ESET MDR?

ESET has a threat research team spread across multiple regions; I’m with the team in Montreal, but we have researchers spread across Europe and in the US, too.

There’s stuff everyone can see: our publications on WeLiveSecurity, and talks and presentations at cybersecurity conferences worldwide.

Then there are things that only ESET business customers get: all kinds of “tips and tricks”; that is, information about threat actors: what they’re doing, how they’re operating – all things that help our customers stay safe.

When it comes to managed detection and response, threat intelligence is a key component that helps our detection and response team understand how the various threat actors are operating and how they can use that information to protect our customers from breaches.

We’ve talked a bit about the tip of the iceberg – all of the back end of MDR that users rarely see, but that is absolutely critical. Could you explain that?

The various alerts that might be occurring in your console will sometimes be endpoint detections that we want to investigate. And my team is responsible for making sure that all the new samples and threats are being handled and detected in customer environments. So part of the team's role is really to make sure that all these new trends, all these new samples are looked at, investigated and then detected on our customers’ premises. This is one of the key aspects.

We take great care in organizing threat intelligence data on e-crime, ransomware, APT groups, and nation-state actors targeting global organizations. Our researchers use these insights to link new breaches with past cases.

They assess the severity of the breach as well, and we can also assess what could be the purpose behind the attack. It really gives the customer a complete view into what might have happened, whether or not a breach happened, or even the specific group that targeted them.

What does MDR add on top of existing ESET endpoint protection?

MDR is more tailored, and the relationship with the customer is improved and increased. But the output of my team is distributed across the entire product set.

There’s been some talk of ESET private reports recently: how relevant are they to what most small and midsize businesses face? Are they facing targeted attacks? What about nation-state actors?

The threat profile will vary from one organization to another, and a nation state actor will typically have predefined goals, and they will be targeting victims that align well with those goals.

In terms of e-crime, this is broad. This is mass targeted. We see a lot of infostealers. We see a lot of ransomware as well.

So, our role is to understand how all these groups operate and make sure that if they have new techniques, we can actually act very swiftly and make sure that we block all the attempts.

This is the ultimate goal, but equally, so many threat actors are out there doing these types of things, and there are so many more families of malware. It’s really a daily job to make sure that the customers are protected. No shortage of work, definitely.

James Rodewald, one of ESET’s security analysts, uses this concept of triangulation: seeing something in the wild, hearing from an affected customer, and checking in with the threat intelligence team. An example he has used is an attack involving FamousSparrow. Can you elaborate on that from your perspective?

It’s important to have close relationships with the people who are actually dealing with these types of cases, because the main role of my team is to look at the telemetry, so the data is gathered from all the endpoints, and we are trying to find interesting cases, and the cases that we need to work on to improve the overall protection.

But sometimes the MDR team stumbles on something that we've seen in the past, and that also allows us to have a greater understanding of how the threat actor is actually operating.

In that specific case, that was eye-opening for us, because we haven't seen this threat actor for quite some time. Whenever there's a case involving a customer using MDR, it's better in terms of research, because the closer relationship with the customer means that we know more about their infrastructure, so we can help them better. We can have a better understanding of the impact of the case. And that is then fed to other threat intelligence customers, so we are trying to be as close as possible to all these teams and link these incidents so that we can improve our coverage and improve our understanding of all these threats.

You talked about the working relationships with the MDR analysts and the D&R (Detection and Response) team. How does that change the way that you do your work and your understanding of threats when you have that kind of one to one relationship with the analysts and maybe the customer as well?

It changes everything, because with MDR, we already have a working relationship with the person who’s in charge of security for this organization, so we can very rapidly understand the scope of the attack, what exactly happened, why the attackers were there, and so on.

The information available to us is exponentially greater than what we can get with regular endpoints. So for us, this relationship is invaluable in terms of insights, visibility and our understanding of the case.

There was something of a spate of attacks in the UK last year that compromised large organizations like Jaguar Land Rover and Marks & Spencer via outsourced helpdesk services. Small and midsized companies also have outsourced services like this as part of their supply chain, and often they’re also the less well-protected parts of a bigger company’s supply chain themselves. Should they be concerned?

The risk posed by supply chain attacks is significant. There have been numerous documented instances over the years where threat actors target vulnerabilities in the supply chain, often focusing on third-party providers with less stringent security measures. By compromising such providers, attackers may obtain initial access to an organization's network.

With respect to MDR, an advantage is the extensive visibility it provides, ensuring a comprehensive view of all detections and alerts. This capability enables us to identify even minor anomalies more effectively. Given that our team continuously monitors these organizations for potential incidents, we are able to detect and respond to subtle threat actor errors promptly.

Supply chain attacks present significant challenges due to the difficulty in securing all third-party entities. However, implementing an effective solution enhances our ability to react swiftly and efficiently to such events.

As the head of a threat research team, what’s the difference that you see MDR having on customers? What's the impact for an organization that has an MDR service, and an organization that might not necessarily make that leap just yet?

In general, as I’ve mentioned before, continuous visibility is much greater with MDR. If your organization is affected by a campaign, you’ll have better tools to piece together all the different actions taken by attackers and understand what they did within your network.

Simply put, MDR provides deeper insight into attacks. From a threat research standpoint, this is the top advantage, and another key reason to value such visibility is the speed of response. With MDR, there’s already a secure channel between researchers and your company, making it easier to reach someone who can take steps to contain a breach quickly.

Final question: What would you say to organizations that might think of MDR as too complicated or expensive?

MDR acts like an insurance policy, helping to identify threats such as ransomware early – often before major problems arise. Attackers typically use initial access brokers to gain entry, but several warning signs can be detected in advance. While paying a ransom is never advised, recovery can still be disruptive. MDR supports business continuity so you can keep focusing on your core offerings.

Thank you!